Iranian Foreign Ministry: "Continuing Message Exchanges with the U.S. and Activities of Mediating Countries"
Esmaeil Baghaei, Spokesperson for the Iranian Ministry of Foreign Affairs [Xinhua, Yonhap News file photo]Esmaeil Baghaei, spokesperson for the Iranian Ministry of Foreign Affairs, stated on the 26th
President Yoon: "Do You Think You Are Safe from the Special Counsel?"... Final Statement Video Released
President Yoon Suk Yeol rebuking the special prosecutor on the 24th. [Court video / @birds_justice X account subtitle GIF] A video of President Yoon Suk Yeol's closing statement at his trial rega
President Yoon, regarding the first-instance ruling on the Public Official Election Act: “An excessive political verdict that distorts the facts… We will appeal immediately.”
The first-instance sentencing hearing for President Yoon Suk Yeol regarding violations of the Public Official Election Act is being broadcast live at Seoul Station on the 27th. [Photo=Yonhap News]Pres
WSJ: "SK Hynix ADR Premium Is a Sign of AI Trading Overheat"
Advertisement for SK Hynix ADR listing in New York's Times Square [Reuters=Yonhap News file photo]The Wall Street Journal (WSJ) has pointed out that the price of SK Hynix’s American Depositary Recei
'Godfather of Japanese Mystery Novels' Keigo Higashino Passes Away After Battle with Cancer at 68
Famous Japanese mystery novelist Keigo Higashino [AFP=Yonhap News]It has been belatedly reported that Keigo Higashino, the "godfather of Japanese mystery novels" and author of bestsellers such as "The
[Park Pil-kyu Security Column] To the Ignorant Trying to Clothe a Beast in Sheep's Clothing
Rep. Kim Byung-joo of the Democratic Party of Korea [Photo=Yonhap News]“The Air Force Academy doesn't teach you how to fly a plane!” “The Army, Navy, and Air Force academies are exactly the
Government Takes Action on Hacking 'Delayed Reporting'…Industry Expresses Concern Over 'Police Power Abuse'
One in five companies required to disclose information security has no dedicated security personnel…Scope of regulated companies to be expanded
Addressing 'corporate arm-twisting' allegations, the government stated, "We will discuss incentives and mitigation for companies that voluntarily report."
Deputy Prime Minister Baek Kyung-hoon announces comprehensive government-wide information security measures (Seoul=Yonhap News) Reporter Lee Jeong-hoon = Deputy Prime Minister Baek Kyung-hoon, also Minister of Science and ICT, announces comprehensive government-wide information security measures at a joint briefing held at the Government Complex Seoul in Jongno-gu, Seoul on the 22nd. 2025.10.22 uwg806@yna.co.kr
Following a series of hacking incidents and delayed reporting, particularly involving mobile carriers, the government has decided to implement strong regulations, including the authority to conduct on-site investigations without prior notification.
The 'Comprehensive Government-Wide Information Security Measures' unveiled on the 22nd by the Ministry of Science and ICT and related ministries include these provisions, along with other punitive measures such as the introduction of punitive fines.
This approach, focusing on immediate, short-term solutions, comes after hacking incidents have affected companies across various sectors, including SK Telecom[017670], KT[030200], Lotte Card, and SK Shieldus.
While intended as a proactive response to recurring delayed reports, the industry has voiced concerns that this could potentially lead to an abuse of police authority.
◇ On-site investigations possible without prior report for suspected hacking…Government to take proactive measures
The comprehensive measures expand the government's investigative authority, allowing on-site inspections without prior company notification when evidence of hacking is obtained.
Deputy Prime Minister and Minister of Science and ICT Baek Kyung-hoon explained, "Previously, investigations could not be conducted if a hacking or breach incident occurred without a report. The biggest difference in this measure is that the government will now conduct ex officio investigations."
Furthermore, the government has taken a firm stance by increasing fines and introducing punitive fines for violations of security obligations, such as delaying hacking reports or failing to implement measures to prevent recurrence.
Deputy Prime Minister Baek stated, "We are conducting policy research to allow for the imposition of fines of up to 3% of total sales for violations of the Information and Communications Network Act, including personal data breaches."
Currently, fines of up to 3% of total sales can be imposed for violations of the Personal Information Protection Act.
The background for these strengthened sanctions is the suspicion that companies intentionally delayed reporting when hacking incidents occurred, leading to delayed initial responses.
The current Information and Communications Network Act requires companies to report incidents to the Korea Internet & Security Agency (KISA) within 24 hours of their occurrence.
However, during the SK Telecom SIM information hacking incident in April, KISA was notified of the breach a full day after the company became aware of the incident.
KT, which experienced unauthorized micro-payments due to illegal base stations, also violated this '24-hour rule,' reporting traces of server intrusion and suspicious circumstances to KISA approximately three days later.
Typically, the first 24 to 48 hours after a hacking incident is considered the 'golden time' to prevent the spread of damage and preserve evidence by identifying server logs, access routes, and exfiltration paths.
Specifically, it has been pointed out that KT's delayed reporting prevented the timely identification of affected base stations and payment routes.
KT branch [Yonhap News file photo. Reproduction and redistribution prohibited]
◇ Industry: "Concerns over abuse of police power & surveillance…need to 'blur' names of companies under investigation"
Some in the industry are raising concerns that the government's expanded investigative authority could lead to an abuse of police power.
An IT industry official expressed concern, stating, "If the government arbitrarily investigates private sectors, it could lead to an abuse of police power or surveillance."
The official added, "If the authority to investigate without prior notification is expanded, it would be necessary to exclude police or intelligence agencies from the initial investigation and only share the results."
There are also calls for increased security regarding the names of companies, as the government's expanded on-site investigations could pose a reputation risk to businesses.
Furthermore, criticism has been raised about the lack of incentives for companies to voluntarily report hacking incidents.
Another telecommunications industry official emphasized, "Currently, there are insufficient incentives for companies to voluntarily report hacking incidents. Policies should be established to encourage faster reporting, considering that companies are also victims of hacking."
Vice Minister of Science and ICT Ryu Je-myeong stated in response, "We will discuss whether incentives can be provided to companies that voluntarily report (hacking incidents) and consider them as grounds for mitigation of related sanctions."
Lotte Card hacking incident consultation center [Yonhap News file photo. Reproduction and redistribution prohibited]
◇ Information security disclosure obligation to be expanded to all listed companies…"Accelerating efforts to strengthen security capabilities"
The industry is also paying close attention to whether the expansion of the information security disclosure obligation, included in the comprehensive measures, could be an effective solution to prevent hacking incidents.
This is because the intended purpose of strengthening security capabilities through mandatory and voluntary disclosure has become largely nominal, with 158 companies (23.7% of the 666 companies currently subject to the obligation) having no dedicated information security personnel as of this year.
An official from the Ministry of Science and ICT explained, "To shift the perception of security from an expense to an investment that determines a company's success or failure, we will expand the scope of companies obligated to disclose information security to all listed companies and publicly disclose their security capability levels by grade."
Meanwhile, there are also complaints that the government, which is also responsible for hacking damage such as the Onnara system hack, is trying to resolve the issue solely through corporate regulation.
In response, Minister Baek stated, "We cannot deny that the government bears significant responsibility. The government wishes to find a joint solution rather than pressuring companies through unconditional sanctions."
The government announced that it has allocated 401.2 billion won, a 7.7% increase from this year, to the information security budget for next year and will announce measures regarding government responsibility in its mid- to long-term information security plans. Yonhap News
Yonhap News More by this author